What Is Cyber Threat Intelligence?
As the IT risk landscape continues to evolve and change at such as rapid pace, the ability to leverage threat intelligence big data in real-time provides organizations with a more proactive and preventative approach to security. The vast volumes and velocity of activity and transactional data that is being generated requires the ability to process it quickly and correlate across a variety of data in order to put the data in a context that is useful to the business in managing cyber-risks in a timely fashion. Critical capabilities include:- Monitoring access activities within key business applications and across transactions for risk notifications and anomaly detection
- Identifying threat actors, their scenarios and behaviors
- Communicating with risk owners and key stakeholders to initiate workflows for remediation and mitigation of risk
Ponemon Research
Context-Aware Security
Context-aware security applies fine-grained, dynamic security policies based on a real-time analysis user activities supplemented with information about identity, role, events, conditions, location, behavior, application, device, data classification, time of day and more. These variable contextual factors are correlated to a baseline of normal or acceptable activity.
Security information and event management (SIEM) create logs of activity and events. Bu not all information sources are available to be monitored, and therefore, not all relevant information is collected and analyzed. Aggregating security data with other relevant process and/or transaction activity data increases the ability to correlate and detect user behaviors or events that will enable faster IT risk identification and prioritizes risks for remediation and mitigation.
Click here to register for the July 27th live webinar Cyber Governance – Key Considerations for Navigating the New Normal to learn more.